Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 28 September 2003 09:46:52 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
Please follow the instructions for removing PE executable viruses.
More Information
W32/Coconut-A is a prepending virus written in C# and also a mass mailing worm.
W32/Coconut-A is a prepending virus written in C# and also a mass mailing worm.W32/Coconut-A places a dropper copy of itself as C:\coconut.exe and temporarily
drops VBS/Coconut-A as C:\mail.vbs. The virus then uses the VBScript to mail
the dropper to all entries in the Windows address book using a mail with the
following characteristics:
Subject: "The Coconut Game"
Message Text: "This game made me feel like I was on a vacation :)"
Attached File: coconut.exe
W32/Coconut-A will then display a 'Coconut Shy' game, in which the user has 3
goes at hitting a picture of either Frans Devaere (for 1 point) or Graham
Cluley (for 2 points) by pressing a button. The virus then infects 6-<score>
files on the system.
